SaTC: CORE: Small: Information Disclosure and Security Policy Design: A Large-Scale Randomization Experiment in Trans-Pacific Region
SaTC:核心:小型:信息披露和安全政策设计:跨太平洋地区的大规模随机实验
基本信息
- 批准号:1718600
- 负责人:
- 金额:$ 33.08万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2017
- 资助国家:美国
- 起止时间:2017-08-01 至 2020-07-31
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
With more prominent data breaches and cybersecurity incidents, cyber insecurity is becoming a serious problem for every individual and the society. Such security incidents are partially due to the lack of relevant governmental polices and the insufficient security protection by organizations managing information assets. The investigators will design an independent Trans-Pacific cybersecurity evaluation institution that measures and reports organizations' security weaknesses. The proposed institution aims at effectively motivating organizations to achieve a desirable level of cybersecurity. An opt-in field experiment with a rigorous design will be employed to empirically evaluate the performance of organizations in the Trans-Pacific region to see how they will respond to the diversified security performance reports of malicious cybercrimes, including spam, phishing, and distributed denial of service (DDoS) attacks. Based on the experimental results, the project will provide practical and credible suggestions to policy makers and companies improve their security preparedness.As methods of data analyses, the researchers will employ potentially useful theoretical and empirical models: (i) a model that allows endogenous experiments, (ii) static and dynamic models with strategic interaction between defenders and attackers, and (iii) a cyber-insurance and reinsurance model which utilizes the PIs' comprehensive security evaluation metric. The PIs will estimate the policy relevant parameters in these models using both experimental and observational data. In addition to the existing dataset on defenders, important data sets that have been collected and will be used in the analyses of the data for attackers, such as data for phishing activity, outgoing spam mails, and real time DDoS information. Since the PIs seek to recover flexible heterogeneous effects of policies, as cybersecurity data typically exhibit a great deal of heterogeneity, they introduce semi-parametric identification and estimation methods developed in the recent econometrics literature. This work contributes to the literature on randomized field experiments in several ways: (i) to identify the problem of endogeneity in randomized field experiments due to the existence of external impact; (ii) in the context of cybersecurity, to redesign a previous experiment and by introducing empirical strategies that control for endogeneity using novel datasets on the attackers; (iii) to recover fully heterogeneous effects of treatments, which departs from a simple and restricted approach commonly taken in the literature; (iv) as some of the datasets are of high frequency (e.g., DDoS real time attack), to develop estimation methods that deal with big data issues. Theoretical models of this project contribute to cybersecurity literature by following novel features: (i) a dynamic cybersecurity game in the continuous-time framework by using stochastic analysis; (ii) a cyber-insurance model with reinsurance opportunity, and specification of the role of governments as the ultimate excessive risk taker, and a method for governments to control organization's cybersecurity investment level by altering the premium.
随着数据泄露和网络安全事件的日益突出,网络不安全正在成为每个人和社会的严重问题。此类安全事件的部分原因是缺乏相关的政府政策以及管理信息资产的组织的安全保护不足。调查人员将设计一个独立的跨太平洋网络安全评估机构,衡量和报告组织的安全弱点。拟议的机构旨在有效激励各组织实现理想的网络安全水平。将采用具有严格设计的选择性现场实验,以实证方式评估跨太平洋地区组织的性能,以了解他们将如何应对恶意网络犯罪的多样化安全性能报告,包括垃圾邮件,网络钓鱼和分布式拒绝服务(DDoS)攻击。根据实验结果,本项目将为政策制定者和企业提供切实可行的建议,以提高其安全防范能力。作为数据分析方法,研究人员将采用潜在有用的理论和经验模型:(i)允许内源性实验的模型,(ii)防御者和攻击者之间具有策略交互的静态和动态模型,以及(iii)利用PI的综合安全评估指标的网络保险和再保险模型。PI将使用实验和观测数据估计这些模型中的政策相关参数。除了现有的防御者数据集之外,还收集了重要的数据集,这些数据集将用于分析攻击者的数据,例如网络钓鱼活动数据、外发垃圾邮件数据和真实的DDoS信息。由于PI寻求恢复政策的灵活异质效应,而网络安全数据通常表现出很大的异质性,因此他们引入了最近计量经济学文献中开发的半参数识别和估计方法。这项工作有助于随机现场实验的文献在几个方面:(一)确定随机现场实验中的问题,由于外部影响的存在;(二)在网络安全的背景下,重新设计以前的实验,并通过引入经验策略,控制使用新的数据集对攻击者的内隐攻击;(iii)恢复处理的完全异质性效应,这与文献中通常采用的简单且受限的方法不同;(iv)由于一些数据集具有高频率(例如,DDoS真实的时间攻击),以开发处理大数据问题的估计方法。该项目的理论模型通过以下新特征对网络安全文献做出了贡献:(i)通过使用随机分析在连续时间框架中进行动态网络安全博弈;(ii)具有再保险机会的网络保险模型,以及政府作为最终过度风险承担者的角色的规范,以及政府通过改变保费来控制组织的网络安全投资水平的方法。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Andrew Whinston其他文献
Understanding Security Vulnerability Awareness, Firm Incentives, and ICT Development in Pan-Asia
了解泛亚洲的安全漏洞意识、企业激励和 ICT 发展
- DOI:
- 发表时间:
2020 - 期刊:
- 影响因子:7.7
- 作者:
Yunhui Zhuang;Yunsik Choi;Shu He;A. Leung;G. Lee;Andrew Whinston - 通讯作者:
Andrew Whinston
Flexible contracting theory and case examples
灵活承包理论和案例
- DOI:
10.1016/0377-2217(79)90115-2 - 发表时间:
1979 - 期刊:
- 影响因子:6.4
- 作者:
Vicente Salas Fumás;Andrew Whinston - 通讯作者:
Andrew Whinston
The Future of the Digital Economy
数字经济的未来
- DOI:
- 发表时间:
2000 - 期刊:
- 影响因子:0
- 作者:
S. Choi;Andrew Whinston - 通讯作者:
Andrew Whinston
Artificial Intelligence and the Management Science Practitioner: Rational Choice and Artificial Intelligence
人工智能与管理科学实践者:理性选择与人工智能
- DOI:
10.1287/inte.18.4.24 - 发表时间:
1988 - 期刊:
- 影响因子:0
- 作者:
V. Jacob;James C. Moore;Andrew Whinston - 通讯作者:
Andrew Whinston
The adoption and design methodologies of component-based enterprise systems
基于组件的企业系统的采用和设计方法
- DOI:
10.1057/palgrave.ejis.3000343 - 发表时间:
2000 - 期刊:
- 影响因子:9.5
- 作者:
Ming Fan;Jan Stallaert;Andrew Whinston - 通讯作者:
Andrew Whinston
Andrew Whinston的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Andrew Whinston', 18)}}的其他基金
TWC: Medium: Reputation as Public Policy for Internet Security
TWC:媒介:作为互联网安全公共政策的声誉
- 批准号:
1228990 - 财政年份:2012
- 资助金额:
$ 33.08万 - 项目类别:
Standard Grant
CT-ISG: Collaborative Research: Incentives, Insurance and Audited Reputation: An Economic Approach to Controlling Spam
CT-ISG:合作研究:激励、保险和审计声誉:控制垃圾邮件的经济方法
- 批准号:
0831338 - 财政年份:2009
- 资助金额:
$ 33.08万 - 项目类别:
Standard Grant
ITR: A Unified Experimental Testbed to Compare Bandwidth Contract Choices for Differentiated Service Networks
ITR:用于比较差异化服务网络的带宽合同选择的统一实验测试台
- 批准号:
0219825 - 财政年份:2002
- 资助金额:
$ 33.08万 - 项目类别:
Continuing Grant
Large-Scale, Long-Term and Virtual Experimental Environments for Electronic Markets
电子市场大规模、长期、虚拟实验环境
- 批准号:
9907935 - 财政年份:1999
- 资助金额:
$ 33.08万 - 项目类别:
Continuing Grant
Workshop: Research Priorities in Electronic Commerce
研讨会:电子商务的研究重点
- 批准号:
9807167 - 财政年份:1998
- 资助金额:
$ 33.08万 - 项目类别:
Standard Grant
Economic Issues for Electronic Commerce
电子商务的经济问题
- 批准号:
9509914 - 财政年份:1995
- 资助金额:
$ 33.08万 - 项目类别:
Continuing Grant
Conference: Frontiers of Electronic Commerce
会议:电子商务前沿
- 批准号:
9521672 - 财政年份:1995
- 资助金额:
$ 33.08万 - 项目类别:
Standard Grant
A General Economic Equilibruim Model of Distributed Computing
分布式计算的一般经济均衡模型
- 批准号:
9225010 - 财政年份:1993
- 资助金额:
$ 33.08万 - 项目类别:
Standard Grant
Distributed Decision Making: A Multiparticipant Decision Support Systems Framework
分布式决策:多参与决策支持系统框架
- 批准号:
8921603 - 财政年份:1990
- 资助金额:
$ 33.08万 - 项目类别:
Standard Grant
The Economic Foundation for Neural Computing Systems
神经计算系统的经济基础
- 批准号:
9005969 - 财政年份:1990
- 资助金额:
$ 33.08万 - 项目类别:
Standard Grant
相似国自然基金
胆固醇羟化酶CH25H非酶活依赖性促进乙型肝炎病毒蛋白Core及Pre-core降解的分子机制研究
- 批准号:82371765
- 批准年份:2023
- 资助金额:50 万元
- 项目类别:面上项目
锕系元素5f-in-core的GTH赝势和基组的开发
- 批准号:22303037
- 批准年份:2023
- 资助金额:30 万元
- 项目类别:青年科学基金项目
基于合成致死策略搭建Core-matched前药共组装体克服肿瘤耐药的机制研究
- 批准号:
- 批准年份:2022
- 资助金额:52 万元
- 项目类别:
鼠伤寒沙门氏菌LPS core经由CD209/SphK1促进树突状细胞迁移加重炎症性肠病的机制研究
- 批准号:
- 批准年份:2022
- 资助金额:30 万元
- 项目类别:青年科学基金项目
基于外泌体精准调控的“核-壳”(core-shell)同步血管化骨组织工程策略的应用与机制探讨
- 批准号:
- 批准年份:2020
- 资助金额:55 万元
- 项目类别:
肌营养不良蛋白聚糖Core M3型甘露糖肽的精确制备及功能探索
- 批准号:92053110
- 批准年份:2020
- 资助金额:70.0 万元
- 项目类别:重大研究计划
Core-1-O型聚糖黏蛋白缺陷诱导胃炎发生并介导慢性胃炎向胃癌转化的分子机制研究
- 批准号:81902805
- 批准年份:2019
- 资助金额:20.5 万元
- 项目类别:青年科学基金项目
原始地球增生晚期的Core-merging大碰撞事件:地核增生、核幔平衡与核幔边界结构的新认识
- 批准号:41973063
- 批准年份:2019
- 资助金额:65.0 万元
- 项目类别:面上项目
RBM38通过协助Pol-ε结合、招募core调控HBV复制
- 批准号:31900138
- 批准年份:2019
- 资助金额:24.0 万元
- 项目类别:青年科学基金项目
CORDEX-CORE区域气候模拟与预估研讨会
- 批准号:41981240365
- 批准年份:2019
- 资助金额:1.5 万元
- 项目类别:国际(地区)合作与交流项目
相似海外基金
SaTC: CORE: Small: An evaluation framework and methodology to streamline Hardware Performance Counters as the next-generation malware detection system
SaTC:核心:小型:简化硬件性能计数器作为下一代恶意软件检测系统的评估框架和方法
- 批准号:
2327427 - 财政年份:2024
- 资助金额:
$ 33.08万 - 项目类别:
Continuing Grant
Collaborative Research: NSF-BSF: SaTC: CORE: Small: Detecting malware with machine learning models efficiently and reliably
协作研究:NSF-BSF:SaTC:核心:小型:利用机器学习模型高效可靠地检测恶意软件
- 批准号:
2338301 - 财政年份:2024
- 资助金额:
$ 33.08万 - 项目类别:
Continuing Grant
Collaborative Research: NSF-BSF: SaTC: CORE: Small: Detecting malware with machine learning models efficiently and reliably
协作研究:NSF-BSF:SaTC:核心:小型:利用机器学习模型高效可靠地检测恶意软件
- 批准号:
2338302 - 财政年份:2024
- 资助金额:
$ 33.08万 - 项目类别:
Continuing Grant
SaTC: CORE: Small: NSF-DST: Understanding Network Structure and Communication for Supporting Information Authenticity
SaTC:核心:小型:NSF-DST:了解支持信息真实性的网络结构和通信
- 批准号:
2343387 - 财政年份:2024
- 资助金额:
$ 33.08万 - 项目类别:
Standard Grant
NSF-NSERC: SaTC: CORE: Small: Managing Risks of AI-generated Code in the Software Supply Chain
NSF-NSERC:SaTC:核心:小型:管理软件供应链中人工智能生成代码的风险
- 批准号:
2341206 - 财政年份:2024
- 资助金额:
$ 33.08万 - 项目类别:
Standard Grant
Collaborative Research: SaTC: CORE: Small: Towards Secure and Trustworthy Tree Models
协作研究:SaTC:核心:小型:迈向安全可信的树模型
- 批准号:
2413046 - 财政年份:2024
- 资助金额:
$ 33.08万 - 项目类别:
Standard Grant
SaTC: CORE: Small: Study, Detection and Containment of Influence Campaigns
SaTC:核心:小型:影响力活动的研究、检测和遏制
- 批准号:
2321649 - 财政年份:2023
- 资助金额:
$ 33.08万 - 项目类别:
Standard Grant
SaTC: CORE: Small: Socio-Technical Approaches for Securing Cyber-Physical Systems from False Claim Attacks
SaTC:核心:小型:保护网络物理系统免受虚假声明攻击的社会技术方法
- 批准号:
2310470 - 财政年份:2023
- 资助金额:
$ 33.08万 - 项目类别:
Standard Grant
Collaborative Research: SaTC: CORE: Small: Investigation of Naming Space Hijacking Threat and Its Defense
协作研究:SaTC:核心:小型:命名空间劫持威胁及其防御的调查
- 批准号:
2317830 - 财政年份:2023
- 资助金额:
$ 33.08万 - 项目类别:
Continuing Grant
Collaborative Research: SaTC: CORE: Small: Towards a Privacy-Preserving Framework for Research on Private, Encrypted Social Networks
协作研究:SaTC:核心:小型:针对私有加密社交网络研究的隐私保护框架
- 批准号:
2318843 - 财政年份:2023
- 资助金额:
$ 33.08万 - 项目类别:
Continuing Grant